CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,108 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 22 of 83
- CVE-2021-30713CRITICALCVSS 7.8EG 9.0⚠ KEV2021-09-08
A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exp…
- CVE-2021-30751MEDIUMCVSS 5.5EG 5.52021-09-08
This issue was addressed with improved data protection. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass certain Privacy preferences.
- CVE-2021-30783MEDIUMCVSS 6.5EG 6.52021-09-08
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. A sandboxed process may be able to circumvent sandbox restricti…
- CVE-2021-30856CRITICALCVSS 9.1EG 9.12021-08-24
This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions. This issue is fixed in macOS Big Sur 11.3. A malicious unsandboxed app on a system with Remote Login enabled may bypas…
- CVE-2021-30925CRITICALCVSS 9.1EG 9.12021-08-24
The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 and iPadOS 15. A malicious application may be able to bypass Privacy preferences.
- CVE-2021-30972MEDIUMCVSS 5.5EG 5.52021-08-24
This issue was addressed with improved checks. This issue is fixed in Security Update 2022-001 Catalina, macOS Big Sur 11.6.3. A malicious application may be able to bypass certain Privacy preferences.
- CVE-2021-30975HIGHCVSS 8.6EG 8.62021-08-24
This issue was addressed by disabling execution of JavaScript when viewing a scripting dictionary. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A malicious OSAX scripting addition may…
- CVE-2021-30987MEDIUMCVSS 5.5EG 5.52021-08-24
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monterey 12.1. A device may be passively tracked via BSSIDs.
- CVE-2021-31158MEDIUMCVSS 6.5EG 6.52021-05-19
In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking the user's permissions, allowing read-access to resources beyond what those users were explicitly allowed to…
- CVE-2021-31165HIGHCVSS 7.8EG 7.82021-05-11
Windows Container Manager Service Elevation of Privilege Vulnerability
- CVE-2021-3153MEDIUMCVSS 6.5EG 6.52021-03-26
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1.
- CVE-2021-31548MEDIUMCVSS 6.5EG 6.52021-04-22
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. A MediaWiki user who is partially blocked or was unsuccessfully blocked could bypass AbuseFilter and have their edits completed.
- CVE-2021-31552MEDIUMCVSS 5.4EG 5.42021-04-22
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules related to blocking accounts after account creation. Such rules would allow for user accounts to be created while bloc…
- CVE-2021-31554MEDIUMCVSS 5.4EG 5.42021-04-22
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It improperly handled account blocks for certain automatically created MediaWiki user accounts, thus allowing nefarious users to remain unblocked.
- CVE-2021-31577CRITICALCVSS 9.8EG 9.82023-02-06
In Boa, there is a possible escalation of privilege due to a missing permission check. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not neede…
- CVE-2021-31590HIGHCVSS 8.8EG 8.82021-07-19
PwnDoc all versions until 0.4.0 (2021-08-23) has incorrect JSON Webtoken handling, leading to incorrect access control. With a valid JSON Webtoken that is used for authentication and authorization, a user can keep his admin privileges even…
- CVE-2021-31601HIGHCVSS 7.1EG 7.12021-11-08
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An…
- CVE-2021-31602HIGHCVSS 5.3EG 8.12021-11-08
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One of these layers is the applicationContext security, which i…
- CVE-2021-31727HIGHCVSS 7.8EG 7.82021-05-17
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 where IOCTL's 0x80002014, 0x80002018 expose unrestricted disk read/write capabilities respectively. A non-privileged process can open a handle to \.\Zema…
- CVE-2021-31728HIGHCVSS 7.8EG 7.82021-05-17
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-privileged process to open a handle to \.\ZemanaAntiMalware, register itself with the driver by sending IOCTL 0x80002010, allocate executabl…
- CVE-2021-31793HIGHCVSS 7.5EG 7.52021-05-06
An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 devices that allows an unauthenticated user to gain access to snapshots and video streams from the doorbell. The binary app offers a web server on port 80 that allows an unauthentica…
- CVE-2021-31829MEDIUMCVSS 5.5EG 5.52021-05-06
kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack ar…
- CVE-2021-31864MEDIUMCVSS 5.3EG 5.32021-04-28
Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler.
- CVE-2021-31865MEDIUMCVSS 5.3EG 5.32021-04-28
Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.
- CVE-2021-31876MEDIUMCVSS 6.5EG 6.52021-05-13
Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes it easier for attackers to trigger a loss of funds, or a denial of service attack against downstream projects such as Li…
- CVE-2021-31926MEDIUMCVSS 6.5EG 6.52021-04-30
AMP Application Deployment Service in CubeCoders AMP 2.1.x before 2.1.1.2 allows a remote, authenticated user to open ports in the local system firewall by crafting an HTTP(S) request directly to the applicable API endpoint (despite not ha…
- CVE-2021-32002MEDIUMCVSS 4.3EG 4.32021-08-05
Improper Access Control vulnerability in web service of Secomea SiteManager allows local attacker without credentials to gather network information and configuration of the SiteManager. This issue affects: Secomea SiteManager All versions …
- CVE-2021-32062MEDIUMCVSS 5.3EG 5.32021-05-06
MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations fr…
- CVE-2021-32076MEDIUMCVSS 5.3EG 5.32021-08-26
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address…
- CVE-2021-32163CRITICALCVSS 9.8EG 9.82023-02-17
Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.
- CVE-2021-32460HIGHCVSS 7.8EG 7.82021-06-03
The Trend Micro Maximum Security 2021 (v17) consumer product is vulnerable to an improper access control vulnerability in the installer which could allow a local attacker to escalate privileges on a target machine. Please note than an atta…
- CVE-2021-32587MEDIUMCVSS 4.3EG 4.32021-08-06
An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker with restricted user profile…
- CVE-2021-32619CRITICALCVSS 9.8EG 9.82021-05-28
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, modules that are dynamically imported through `import()` or `new Worker` might have been able to bypass network and file s…
- CVE-2021-32620HIGHCVSS 8.8EG 8.82021-05-28
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 11.10.13, 12.6.7, and 12.10.2, a user disabled on a wiki using email verification for registration canouldre-acti…
- CVE-2021-32701HIGHCVSS 7.5EG 7.52021-06-22
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. When you make a request to an endpoint that requires the scope `foo` using an access token gran…
- CVE-2021-32716MEDIUMCVSS 4.4EG 4.42021-06-24
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidden fields when an association has been loaded with a to many reference. Users are recommend to update to version 6.4.1.…
- CVE-2021-32777HIGHCVSS 8.6EG 8.62021-08-24
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions when ext-authz extension is sending request headers to the external authorization service it must merge m…
- CVE-2021-32779HIGHCVSS 8.6EG 8.62021-08-24
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy incorrectly handled a URI '#fragment' element as part of the path element. Envoy is configured with…
- CVE-2021-32829CRITICALCVSS 9.6EG 9.92021-08-17
ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of compute, storage, and networking all by APIs. Affected versions of ZStack REST API are vulnerable to post-authentication…
- CVE-2021-32960HIGHCVSS 8.5EG 8.82022-04-01
Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on …
- CVE-2021-32986CRITICALCVSS 9.8EG 9.82022-04-04
After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not timeout. If the programming software is interrupted, the PLC remains unlocked. All subseq…
- CVE-2021-33058HIGHCVSS 7.8EG 7.82021-11-17
Improper access control in the installer Intel(R)Administrative Tools for Intel(R) Network Adaptersfor Windowsbefore version 1.4.0.21 may allow an unauthenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-33118HIGHCVSS 7.8EG 7.82021-11-17
Improper access control in the software installer for the Intel(R) Serial IO driver for Intel(R) NUC 11 Gen before version 30.100.2104.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-33119MEDIUMCVSS 5.5EG 5.52022-02-09
Improper access control in the Intel(R) RealSense(TM) DCM before version 20210625 may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2021-3332MEDIUMCVSS 5.3EG 5.32021-03-01
WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password.
- CVE-2021-33335HIGHCVSS 7.2EG 7.22021-08-03
Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows remote authenticated users with permission to update/edit users to take over a company admin…
- CVE-2021-33346CRITICALCVSS 9.8EG 9.82021-06-24
There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this vulnerability to modify the password of the admin user without authorization.
- CVE-2021-3337HIGHCVSS 7.5EG 7.52021-01-28
The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit.
- CVE-2021-33504MEDIUMCVSS 4.9EG 4.92022-06-02
Couchbase Server before 7.1.0 has Incorrect Access Control.
- CVE-2021-33577MEDIUMCVSS 5.3EG 5.32021-06-18
An issue was discovered in Cleo LexiCom 5.5.0.0. The requirement for the sender of an AS2 message to identify themselves (via encryption and signing of the message) can be bypassed by changing the Content-Type of the message to text/plain.
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →